CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25824  CVE-2007-2467  Candidate  ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access.  Assigned (20070502)  None (candidate not yet proposed)    View
28401  CVE-2007-5044  Candidate  ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreatePort and (2) NtDeleteFile kernel SSDT hooks, a partial regression of CVE-2007-2083.  Assigned (20070923)  None (candidate not yet proposed)    View
1798  CVE-2000-0220  Candidate  ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.  Proposed (20000322)  ACCEPT(1) Armstrong | MODIFY(1) Frech | NOOP(5) Baker, Cole, LeBlanc, Ozancin, Wall | REJECT(1) Blake | REVIEWING(1) Levy  Blake> Discussion on Bugtraq shows that this is a really marginal issue. Very | tough to come up with a viable attack scenario. Also, it"s part of how | this class of software works, not a flaw in the cited package. Might be | possible to recast this into something more generic.... | Frech> XF:zonealarm-exposes-info  View
36872  CVE-2008-6755  Candidate  ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.  Assigned (20090427)  None (candidate not yet proposed)    View
36873  CVE-2008-6756  Candidate  ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.  Assigned (20090427)  None (candidate not yet proposed)    View

Page 20930 of 20943, showing 5 records out of 104715 total, starting on record 104646, ending on 104650

Actions